Cyber Threat Exposure Management Analyst (Bengaluru)

Cyber Threat Exposure Management Analyst (Bengaluru)

11 Sep
|
Version 1
|
Bengaluru

11 Sep

Version 1

Bengaluru

Job Description

We are seeking a Cyber Threat Exposure Analyst to support our exposure management programme across the estate. The role spans vulnerability management, attack surface management, cloud security posture, and secure development practice. Working as a fully contributing team member, you will own end-to-end vulnerability lifecycle activity, maintain prioritised exposure views, and communicate risk clearly to internal stakeholders. You operate with limited supervision, take clear ownership of your assignments, and consistently deliver to a high standard of quality.

Key Responsibilities

Attack Surface Management (ASM / EASM)

- Maintain a continuous inventory of Internet-facing assets, shadow IT, domains, subdomains, certificates, cloud services, APIs, and third-party-hosted assets.
- Operate EASM/CAASM tooling to surface unowned or unmanaged assets and route them to the correct owner.
- Enrich attack surface findings with threat intelligence, active exploitation trends, and KEV data to support prioritisation.
- Proactively identify gaps in asset coverage and bring forward improvement ideas without waiting to be directed.

Vulnerability Management

- Own the end-to-end vulnerability lifecycle: identification, risk-based triage, remediation tracking, and closure validation.
- Apply CVSS, EPSS, and business context to set remediation SLAs and escalation paths.
- Maintain vulnerability management policies, standards, and reporting cadence aligned to ISO 27001 and NIST CSF.
- Break down complex vulnerability backlogs into prioritised, actionable components and drive them to closure with minimal supervision.

Cloud Security Posture Management (CSPM)

- Monitor cloud misconfigurations, identity risk, and posture drift across AWS, Azure, and OCI.
- Partner with cloud platform teams to remediate CSPM findings and reduce recurring misconfiguration classes.
- Extend CSPM coverage as new cloud services, apps, and workloads are onboarded.




- Build and maintain strong working relationships with platform and engineering teams; negotiate remediation timelines and handle pushback constructively.

CTEM / Exposure Management

- Operate the Scope, Discover, Prioritise, Validate, and Mobilise phases of the CTEM programme.
- Consolidate attack surface, vulnerability, and posture data into a single exposure view for stakeholders.
- Track and report exposure reduction metrics against agreed KPIs, maintaining accurate and well-organised records across all workstreams.

Secure SDLC

- Embed security requirements, threat modelling, and secure code review checkpoints into the SDLC.
- Work with engineering teams to reduce vulnerability injection at source rather than relying only on downstream remediation.
- Maintain secure-by-design standards and guidance for development teams.

Pentest & Purple Team Support

- Support the commission and management of third-party penetration testing and purple team engagements.
- Review scope, rules of engagement, and quality of third-party findings before acceptance.
- Translate external test results into prioritised, actionable remediation guidance for internal teams.

Reporting & Stakeholder Communication

- Produce dashboards and reports translating technical exposure data into business risk language for senior stakeholders.
- Present exposure trends, remediation progress, and residual risk to management and audit/compliance functions.
- Support audit and certification cycles (ISO 27001, Cyber Essentials Plus, SOC 1, client MSP audits) with evidence of exposure management practice.
- Adapt communication style to the audience; explain technical risk clearly to non-technical colleagues and business stakeholders.

Ways of Working

- Meet all team commitments and deadlines; support colleagues encountering blockers and contribute to a collaborative team environment.
- Seek out and act on feedback; treat problems as learning opportunities and continuously update skills and knowledge.
- Adapt readily to changing priorities, current tooling, and evolving threat landscapes without disruption to delivery quality.
- Live and demonstrate Version 1 Core Values in everyday work, acting as a visible example for more junior colleagues.

📌 Cyber Threat Exposure Management Analyst (Bengaluru)
🏢 Version 1
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cyber threat exposure management analyst (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: cyber threat exposure management analyst (bengaluru) / bengaluru